Payment Institution License in Spain

We structure your project and defend your payment institution license application before the Bank of Spain: regulatory fit analysis, programme of operations, complete application file, safeguarding of funds, AML/CFT, corporate governance and ongoing compliance.

100% Free

Need a PI license? Free assessment

Tell us about your business model and we will tell you whether you fit as a PI, an EMI or a PISP/AISP before the Bank of Spain.

+50 entities advised24h responseNo obligation

Quick answer

A payment institution (PI) license in Spain is the Bank of Spain authorization to provide payment services on a professional basis under PSD2 and Royal Decree-law 19/2018. It requires initial capital of €20,000 to €125,000 depending on the services, safeguarding of client funds and a complete application file with a programme of operations. The statutory deadline for a decision is 3 months; in practice, it takes 6 to 12 months.

A different application file for every fintech project

Payment platforms, fintechs with wallets, PISP/AISP models or operators that want their own license: every project has its own regulatory fit and its own specific requirements.

Authorization

Regulatory fit as a payment institution

"Before opening the application file, you need to confirm whether your model really fits as a payment institution and which services you will provide. That decision shapes everything else."

Bank of Spain

A solid, consistent application file

"You don't win a payment institution license with nice-looking documents: you need consistency between business, governance, policies, technology, third parties and evidence."

Operations

Payment services and safeguarding

"The operating structure has to hold up in practice: funds, reconciliations, incidents, customer service, critical providers and controls that stand up to review."

Compliance

AML/CFT and ongoing control

"Authorization is not the finish line. A payment institution needs working AML/KYC, internal control, reporting, training and constant monitoring from day one."

Why is the PI license critical for your project?

Operating without a license, filing an inconsistent application or improvising ongoing compliance can block your operations, your fundraising and your banking relationships.

The most common mistake: launching a payment solution without first working out whether the activity requires a license. The problem surfaces once the product is already built, and the cost of fixing it soars.

The Bank of Spain reviews consistency, not just documents: if the business, policies, governance, AML/KYC and outsourcing do not fit together, the application loses strength and information requests multiply.

Safeguarding and internal control cannot be left until the end: they are central to making the license defensible and to letting the institution scale safely.

Very serious infringementImmediate cessation

Providing payment services without prior authorization can lead to the immediate shutdown of the activity.

Financial penaltiesSubstantial

Fines and personal liability for directors for providing financial services without a license.

Commercial riskOperational lockout

Banks and financial partners require an active license before integrating a fintech into their ecosystem: without one, deals stall indefinitely.

Does your model need a payment institution license?

Before opening the application file, it pays to validate the regulatory perimeter, put the business in order and check whether your structure can meet the requirements for authorization, safeguarding, AML/CFT and ongoing control.

PI license: frequently asked questions

What is a payment institution license?

The payment institution license is the authorization to provide certain payment services on a professional basis within the regulatory framework that applies in Spain. It is not a banking license or an EMI license: it has its own regulatory perimeter.

The key is not just obtaining the license, but being able to run an institution that can be supervised from day one: controls in operation, funds safeguarded and compliance that is actually alive.

When does a company need a payment institution license?

When the model enters the chain of payment execution, order handling or operations with client funds, and can no longer be presented as a purely technological or ancillary activity.

The usual mistake is to assume that having a software layer means there is no regulated activity. That misunderstanding tends to break the project when partners, product and investment are already committed.

What is the difference between a payment institution, an EMI and a bank?

Each license type has a different regulatory perimeter and its own requirements depending on the service you want to provide:

  • A payment institution (PI) provides payment services without issuing electronic money.
  • An electronic money institution (EMI) can also issue electronic money (wallets, prepaid cards, stored balances).
  • A bank can take deposits from the public, which greatly widens its perimeter and its capital and supervisory requirements.

Choosing the wrong license type from the outset delays the whole process and may force you to restructure your business model.

What does the Bank of Spain review in the application file?

It reviews whether the application file is consistent, complete and defensible: programme of operations, corporate structure, directors, key functions, internal policies, control system, third parties, technology and real capacity to operate.

The supervisor checks whether the business described can be sustained by people, processes, contracts, controls and evidence that make sense together. Document consistency matters as much as the legal content.

Why are safeguarding and AML/CFT so important?

Safeguarding of funds and the AML/CFT framework are two central pieces of a payment institution, not secondary annexes. They affect the quality of the application, the relationship with banking partners and the future strength of the institution.

They force you to set out in practice the flow of funds, reconciliations, onboarding, monitoring, reporting, internal roles and evidence. When they are improvised, the supervisor spots it quickly.

How long does it take to obtain a payment institution license?

The statutory deadline for a decision is 3 months from the filing of the complete application, although in practice the process can stretch to 6-12 months depending on the complexity of the model and the quality of the application file.

What usually makes a license more expensive and slower is not drafting it, but fixing it: redoing annexes, clarifying contradictions, answering information requests or redesigning parts of the business that had not been properly closed.

Can I operate while my license application is pending?

As a general rule, no. Providing payment services without prior authorization is a very serious infringement.

There are some limited exceptions (an exemption regime for very small volumes, ancillary activities) that must be analyzed case by case. The usual alternative while your own license is being processed is to operate under the umbrella of an already authorized institution through an agent or regulated distribution agreement.

What happens after you obtain the license?

The most important phase begins: operating as a supervised institution with ongoing compliance, internal control, incident follow-up, third-party oversight, training and reporting.

  • Maintaining AML/KYC controls and active monitoring.
  • DORA compliance: ICT risk management, business continuity, incident reporting.
  • Periodic reporting to the Bank of Spain and handling of information requests.
  • Ongoing review of critical third parties, SLAs and outsourcing.
  • Periodic audits and updating the framework as regulations change.

The license is not the end of the project: it is the starting point of supervised operations.

How much does it cost to obtain a payment institution license?

There is no single figure: the cost varies with the model, the range of services and the project's starting point. The factors that drive the cost are:

  • Minimum capital: between €20,000 and €125,000 depending on the payment services to be provided (cash placement on an account, cash withdrawal, execution of payment transactions, issuing of payment instruments, money remittance or payment initiation).
  • Legal and regulatory advice: regulatory fit, drafting the application file, internal policies and handling information requests from the Bank of Spain.
  • Internal structure: key functions (compliance, AML, audit, risk), fitness and propriety of directors and, where appropriate, outsourcing of some functions.
  • Technology and critical providers: agreements with banks for safeguarding, KYC/AML systems, monitoring, DORA framework.
  • Ongoing compliance: periodic audits, training, reporting and regulatory updates (PSD3, AMLR).

What stretches out the process and drives up the cost is not drafting the application file, but fixing it: a regulatory fit that was poorly defined at the start costs months and extra rounds of information requests.

Does a marketplace or platform need a payment institution license?

It depends on the actual flow of funds. If the platform:

  • Receives payments from buyers and holds them before paying sellers → it probably does need a PI license (or must work with an authorized PI/EMI as an agent or partner).
  • Uses a payment provider that separates the flows and never touches the money → it can operate without a license, but the contract and documentation must show this clearly.
  • Runs "split payments" or pooled collections with later settlement → it almost always falls within the regulated perimeter.

The usual mistake is to assume that using Stripe, Adyen or another provider means you carry out no regulated activity of your own. The reality depends on the contractual and technical design of the flow, not on the tools you use.

Is it better to operate as an agent of a PI or to apply for your own license?

Each option makes sense at a different stage:

  • Agent of an authorized PI: fast time-to-market (weeks instead of months), lower initial cost, but dependence on the principal institution's policies, systems and rate card. Suitable for validating product-market fit or launching quickly.
  • Your own license: a 6-12 month process and a larger initial investment, but full control over operations, European expansion through passporting, a better valuation from investors and more bargaining power with banks. It is a strategic asset.

Many projects start as an agent and, once the model is validated, apply for their own license. The transition must be planned well in advance, because changing the regulatory status affects clients, contracts and operations.

What documents does the Bank of Spain require in the application file?

The PI license application file includes, among other documents:

  • Programme of operations report: payment services to be provided, business model, clients, channels and projections.
  • Corporate structure: deed of incorporation, paid-up capital, organization chart, identification of qualifying shareholders.
  • Fitness and propriety of directors and key function holders: CVs, commercial and professional good repute, experience and availability.
  • Internal policies: safeguarding, AML/CFT, internal control, risk management, conflicts of interest, market conduct.
  • Technology and DORA framework: architecture, ICT risk management, business continuity, critical providers and resilience testing plan.
  • Outsourcing: contracts, SLAs, controls and an exit plan for contingencies.
  • Operating procedures: KYC/onboarding, monitoring, incident management, customer service and complaints.

The quality and consistency across these documents carries as much weight as the correctness of each one on its own.

How does PSD3 affect payment institutions?

As of July 2026, PSD3 and the PSR Regulation are still going through the EU legislative process and do not yet apply: your license is governed by PSD2 (Royal Decree-law 19/2018). Once adopted, the reform is expected to fold EMIs into the payment institution category, tighten anti-fraud controls (payee verification, SCA) and open a transitional re-authorization period for institutions that are already licensed.

In practice: don't wait for PSD3 to apply for your license — obtaining it now with a solid application file gives you an edge in the transition — but design your policies and technology with the new requirements in mind.

The 8 payment services that require a PI license in Spain

Catalog of payment services in Article 1.2 of Royal Decree-law 19/2018 (which replaced Law 16/2009). If your model fits any of these services, the activity is regulated and you need a payment services license from the Bank of Spain.

1

Cash placement on a payment account

Services enabling cash to be placed on a payment account, and all the operations required to operate that account.

2

Cash withdrawal

Services enabling cash to be withdrawn from a payment account, and all the operations required to operate it.

3

Execution of payment transactions

Direct debits, card payments and credit transfers, including those carried out through a credit line.

4

Execution with a credit line

The same transactions as in point 3 where the funds are covered by a credit line granted to the user.

5

Issuing of payment instruments

Issuing and acquiring of payment instruments (cards, devices, credentials) by authorized providers.

6

Money remittance

Transactions in which funds are received without opening a payment account, for the sole purpose of transferring them to a payee.

7

Payment initiation (PISP)

Initiating a payment order at the user's request in respect of an account held with another payment service provider.

8

Account information (AISP)

Online services that provide consolidated information on the user's payment accounts held with other providers.

Does your product fit any of these? You very likely need a PI license, an EMI license or a PISP authorization or an AISP registration. Download the free checklist or request an assessment.

Payment institution vs EMI vs PISP/AISP vs bank

The four regulated license types that are most often confused, side by side: minimum capital, client funds, complexity of the application file and real timelines.

Feature Payment institution (PI) EMI (electronic money) PISP / AISP Bank
Minimum capital €20,000 – €125,000 €350,000 €50,000 (PISP) / No minimum (AISP, professional indemnity insurance required) €5,000,000
Client funds Receives and executes payments (with safeguarding) Receives, stores (electronic money) and executes payments Does not handle client funds Takes deposits and provides financial services
Typical services Transfers, direct debits, card payments, remittances Wallets, prepaid cards, stored balances, e-wallets Payment initiation (PISP) / Account aggregation (AISP) Deposits, lending, mortgages, corporate banking
Safeguarding of funds Mandatory (segregated accounts or insurance) Mandatory (segregated accounts or insurance) Not applicable (no client funds held) Subject to the banking prudential regime
DORA applies Yes (since January 2025) Yes (since January 2025) Yes (since January 2025) Yes (since January 2025)
Average real timeline 6 – 12 months 9 – 15 months 3 – 6 months 18 – 36 months
Supervision Bank of Spain Bank of Spain Bank of Spain (registration) Bank of Spain / ECB (SSM)
EU passport Yes (notification to the host regulator) Yes (notification to the host regulator) Yes (notification to the host regulator) Yes (notification to the host regulator)
Typical business model Processors, remittance companies, B2B platforms, marketplaces with a flow of funds Neobanks, wallets, prepaid cards, platform e-wallets Payment initiation apps, financial aggregators, PFM, scoring Universal or digital banking that takes deposits

Indicative figures based on Royal Decree-law 19/2018, Law 21/2011 on electronic money and the applicable banking regulations. Each case requires an individual analysis of the perimeter and the specific services to be provided.

Which license type does your model need?

Six common fintech business models and the license type that usually fits them. The final decision depends on the actual flow of funds and the specific services provided.

💱
Recommended: PI

International remittance platform

Receives funds in Spain for payees abroad. No issuing of electronic money.

Typical services: money remittance (service 6), execution of payment transactions (service 3).
🛍️
Recommended: PI / Partner

Marketplace with split payments

A marketplace that collects from buyers and pays out to sellers, keeping its own commission. If it holds funds, it falls within the regulated perimeter.

Typical services: execution of payment transactions (service 3), money remittance (service 6) if it settles to third parties.
💳
Recommended: EMI

Wallet or prepaid card

Balance stored on the user's behalf, top-ups, prepaid card payments. It involves issuing electronic money.

Typical services: issuing of electronic money, issuing of payment instruments (service 5), cash placement on an account (service 1).
🏢
Recommended: PI

B2B fintech with virtual accounts

Virtual accounts for businesses with their own IBANs, management of collections and payments, automated reconciliation.

Typical services: cash placement on an account (service 1), cash withdrawal (service 2), execution of payment transactions (service 3).
📊
Recommended: AISP

Financial aggregator / PFM

An app that connects the user's bank accounts to show balances, spending or scoring. It does not handle client funds.

Typical services: account information (service 8 – AISP).
🔁
Recommended: PISP

Account-to-account payment app

A solution that initiates transfers from the user's account to a payee, without going through a card.

Typical services: payment initiation (service 7 – PISP).

Can't find your model here? Tell us about your project and we will tell you exactly which license type you need and why.

How much does a payment institution license in Spain cost?

There is no single price. The total cost depends on five factors and, above all, on the range of services you ask to have authorized. Below we break them down and give you a calculator to estimate your statutory minimum capital.

1 · Capital

Statutory minimum capital

€20,000 – €125,000

Under Royal Decree-law 19/2018, depending on the payment services to be provided. It is the only item for which the regulator sets an exact numerical minimum.

2 · Advice

Legal and regulatory advice

Variable

Regulatory fit, drafting of the application file, internal policies, handling of information requests and operational support throughout the process before the Bank of Spain.

3 · Structure

Internal structure and key functions

Recurring

Fit and proper directors, compliance officer, AML/internal control body (OCI), internal audit and risk. They can be in-house staff or outsourced to a qualified provider.

4 · Technology

Technology and critical providers

Variable + recurring

Banking agreements for safeguarding, KYC/AML systems, transaction monitoring, DORA framework, payment infrastructure and cybersecurity.

5 · Compliance

Ongoing post-authorization compliance

Recurring, annual

Periodic reporting, audits, team training, adapting to regulatory changes (PSD3, AMLR) and active handling of the supervisor's information requests.

+ Hidden

The hidden cost: fixing a poor regulatory fit

3-6 extra months

Starting the application file without having properly settled the license type is the main cause of cost overruns: redoing annexes, answering information requests and redesigning the business.

Minimum capital of a payment institution in Spain under article 5 of Royal Decree-law 19/2018: €20,000 for money remittance, €50,000 for payment initiation (PISP) and €125,000 for services 1 to 5; no minimum capital for AISPs and €350,000 for EMIs
Minimum initial capital of a payment institution by services applied for (art. 5 of Royal Decree-law 19/2018). If several services are applied for, the highest amount applies. © Molina Law Boutique.

Practical guide: the payment institution license

A PI license is not just a formality: it is a system that must show consistency between business model, operations, controls and evidence. The key is to build, from the start, an institution that can withstand real supervision.

Application file

What the supervisor really looks for

The Bank of Spain does not just review the business idea. It analyzes whether the structure can sustain it: fit and proper directors, key functions, consistent policies, workable controls and evidence of real operational capacity.

Safeguarding

The piece most often improvised

The flow of funds, reconciliations, account segregation and incident management must be designed before the application file, not as an appendix. A failure here blocks authorization.

Ongoing compliance

The license is the beginning, not the end

Working AML/KYC, DORA, reporting, audits and handling of the supervisor's information requests must be designed to last over time, not just to get the initial application through.

PI checklist: preparation in 10 steps

  1. Regulatory fit: confirm whether the model requires a PI license and which specific payment services will be provided.
  2. Right license type: analyze whether a PI is the right choice compared with an EMI, PISP/AISP or other authorizations.
  3. Corporate structure: company, minimum capital, shareholders, directors and demonstrable fitness and propriety.
  4. Programme of operations: a consistent description of the business, clients, channels, technology and partners.
  5. Governance and key functions: organization chart, segregation of duties, heads of compliance, audit and risk.
  6. Safeguarding of funds: define the flow, accounts, reconciliations, incident management and traceability.
  7. AML/CFT framework: risk assessment, KYC/onboarding, monitoring, escalation and training.
  8. Outsourcing and critical third parties: contracts, SLAs, security, continuity and documented subcontracting.
  9. DORA: ICT risk management, business continuity policy, incident register and critical providers.
  10. Ongoing compliance: design post-authorization reporting, audits and handling of information requests from the start.

If you want to structure your application file from scratch or review where your project stands, see our fintech regulation services or our dedicated fintech compliance practice.

Infographic showing the roadmap to a payment institution license in Spain in 4 phases: regulatory fit (2-4 weeks), building the application file, Bank of Spain review (3 months by law, 6-12 months in practice) and ongoing compliance as a supervised institution
The 4 phases of the payment institution license before the Bank of Spain, under PSD2 and Royal Decree-law 19/2018. © Molina Law Boutique.
The PI license in operational mode

From idea to application file: how a payment institution is built

An effective payment institution license is not a dossier: it is a set of consistent decisions (regulatory fit, safeguarding, AML/KYC, governance and outsourcing) backed by traceable evidence. Here is a visual overview of how it works in practice.

Regulatory fit of a payment institution1) Fit

Regulatory fit: define first, then apply

The goal is not to "get the license faster": it is to make sure the model needs one, of which type and with what perimeter. That decision shapes the entire application file.

  • Analysis of the actual service (not the commercial name)
  • PI vs EMI vs PISP/AISP comparison
  • Perimeter of the regulated activity
Bank of Spain application file for a PI license2) Application

Application file: consistency across every piece

The supervisor checks consistency. Programme of operations, policies, governance, technology and outsourcing must fit together without internal contradictions.

  • Detailed programme of operations
  • Internal policies and risk map
  • Fitness and propriety of directors
Safeguarding of funds at a payment institution3) Safeguarding

Safeguarding: the most improvised piece

Flow of funds, segregated accounts, reconciliations and incidents. When it is designed late, it blocks authorization or creates structural gaps after the license is granted.

  • Flow and segregation of funds
  • Reconciliations and incidents
  • Traceability of flows
Decision map for the PI license and regulatory license typeQuick decision

Practical map: which license type does your project need?

Payments only

PI license: transfers, direct debits, card payments or remittances without issuing electronic money.

Wallets / prepaid

EMI license: you issue electronic money (stored balance, prepaid card). Higher capital requirements.

Open banking

PISP authorization / AISP registration: you initiate payments or aggregate bank accounts without handling client funds.

See our fintech regulation servicesEMI license
PI playbook

The PI license in practice

Application block
What is expected
Typical evidence

Regulatory fit

A reasoned analysis showing that the actual activity requires a PI license and not another license type (EMI, PISP, unregulated activity).

Regulatory fit report, description of the actual service and comparison of license types.

Programme of operations

A consistent description of the business, clients, channels, technology and partners that supports the supervisor's review.

Detailed business report, projections, third-party contracts and functional organization chart.

Safeguarding of funds

A clear flow of client funds, segregated accounts, reconciliations and properly handled incidents.

Safeguarding policy, description of the flow of funds, banking agreements and reconciliation procedures.

AML/KYC (AML/CFT)

Risk assessment, onboarding, monitoring and reporting proportionate to the business's risk profile.

AML/CFT manual, KYC files, alert log and evidence of staff training.

Governance and control

Fit and proper directors, key functions, segregation of responsibilities and an internal control system.

Minutes, appointments, conflicts of interest policy, risk map and annual audit plan.

Common mistakes that delay or block the license

Spot them before filing the application to avoid costly information requests.

  • Starting with the application file before settling the regulatory fit.
  • Treating legal, product, technology and operations as separate worlds.
  • Designing safeguarding and AML/CFT as appendices to the application instead of central pieces.
  • Directors who cannot demonstrate fitness, propriety and independence to the supervisor.
  • Outsourcing without contracts, SLAs or a documented continuity framework.

PSD3 and the Payment Services Regulation (PSR): what will change for your license

The EU is revising the payments framework: the PSD3 directive and the Payment Services Regulation (PSR). As of July 2026 they do not yet apply — your license is governed by PSD2 — but it makes sense to design your application file today with them in mind.

PIs and EMIs, heading towards a single regime

The proposal brings electronic money institutions in as a category within payment institutions. If you are torn between a PI and an EMI today, the line will become thinner: decide your regulatory fit with that convergence in mind.

Tougher anti-fraud requirements

Payee verification (confirmation of the account holder), stronger authentication (SCA) and new liability rules for fraud. The monitoring you design today will need to absorb these controls.

Re-authorization with a transitional period

Institutions already authorized under PSD2 will have a transitional period to adapt to the new framework. Obtaining the license now with a solid application file gives you an edge in that transition.

Status as of July 2026: PSD3 and the PSR are still going through the legislative process in the Council and the European Parliament, with no final application date. We track each milestone and update this page as things progress.

6 mistakes that cost months (and thousands of euros) in the application process

The statutory deadline is 3 months, but most applications stretch to 6-12 because of the same recurring mistakes. These are the ones we see most often and how to avoid them.

1

Starting the application file without settling the regulatory fit

The project applies for a PI license when it actually needs an EMI license (because it issues electronic money), or applies for both services when one would do. Result: oversized capital, a reopened application file and months lost.

How to avoid it: spend an initial 2-4 weeks on a signed regulatory fit report that analyzes the actual service (not the commercial name) and compares PI, EMI, PISP/AISP and the agent route.
2

Keeping legal, product, technology and operations apart

The application file describes a business that does not match what the tech team is building. The Bank of Spain detects contradictions between the programme of operations, the architecture and the contracts.

How to avoid it: cross-functional meetings with legal, product, the CTO and operations from the regulatory fit phase. One person must be responsible for document consistency.
3

Designing safeguarding as an annex to the application file

The flow of funds is written up at the end, with no signed banking agreements and no detailed reconciliation procedure. It is the #1 cause of blocked payment authorizations.

How to avoid it: start talks with banks about segregated accounts in parallel with the programme of operations, not afterwards. Design safeguarding in phase 2, not phase 3.
4

Directors without demonstrable fitness and propriety

The proposed directors are brilliant in technology but lack financial experience or real availability. The Bank of Spain requires good repute, experience and genuine time commitment.

How to avoid it: define the organization chart and each director's real time commitment before filing the application. Consider bringing in a senior profile with a regulatory track record.
5

Outsourcing without contracts or DORA clauses

Critical technology providers are engaged on a standard SaaS MSA. DORA requires specific clauses, audit rights, an exit plan and a register of critical providers.

How to avoid it: review and renegotiate contracts with critical providers in phase 2 of the application, not after authorization. The Bank of Spain asks for the register.
6

Generic AML/KYC copied from another project

A standard AML manual is submitted with no business-specific risk assessment, no tailoring to the actual type of client, and no formal appointment of the internal control body (OCI) or SEPBLAC representative.

How to avoid it: an AML risk assessment specific to the business model, a KYC policy adapted to the actual client profile and the appointment of an OCI with recognized experience.

European passport: operate across the EU with your PI license

One of the big strategic advantages of getting licensed in Spain: the European passport lets you provide payment services in all 27 EU countries without applying for additional authorizations.

One license, 27 markets

Under the PSD2 Directive, payment institutions authorized in any EU Member State can operate in the others through the freedom to provide services or the freedom of establishment (opening a branch or using agents).

The process is a notification to the Bank of Spain, which passes it on to the regulator of the host country. It is not a second authorization: if your license is solid in Spain, it is solid across the EU.

  • Freedom to provide services (FPS) without a physical presence
  • Opening a branch in another Member State
  • Network of agents in EU countries
  • Prior notification to the host regulator via the Bank of Spain
  • Home-country supervisory framework remains in place

Markets you can access through passporting

🇩🇪Germany
🇫🇷France
🇮🇹Italy
🇵🇹Portugal
🇳🇱Netherlands
🇧🇪Belgium
🇮🇪Ireland
🇦🇹Austria
🇵🇱Poland
🇸🇪Sweden
🇩🇰Denmark
+16more

All 27 Member States + the European Economic Area (Norway, Iceland, Liechtenstein) under the EEA arrangements.

Why fintechs and payment institutions trust Molina Law Boutique

A boutique firm specialized in financial regulation. We work exclusively with projects that need Bank of Spain licenses and regulatory compliance: that focus is what makes the difference.

+50

Regulated entities advised

Payment fintechs, EMIs, PISPs/AISPs, AML obliged entities and financial institutions. We know the Bank of Spain's real criteria, not just the theory.

100%

Regulatory focus

We are not a generalist firm with a fintech department: financial regulation is all we do. That lets us move faster and get straight to the point.

24h

Real responsiveness and availability

We answer queries in under 24 hours and work side by side with the client's team. No gatekeepers and no juniors reviewing case law: you deal directly with the lawyer in charge.

E2E

From regulatory fit to live compliance

We support you from the initial assessment through to post-authorization reporting: regulatory fit, application file, handling of information requests, AML, DORA and ongoing compliance.

Working glossary

Key concepts: the payment institution license

If you are structuring a PI license, these terms come up in the application file, in internal policies and in your dealings with the supervisor. Understanding them well helps you build a consistent project.

Payment institutionBasics

PI – Payment Institution (EP)

An institution authorized to provide payment services on a professional basis: transfers, direct debits, remittances, card payments or payment initiation.

Governed by: PSD2 / Royal Decree-law 19/2018.
EMIElectronic money

Electronic money institution

It can issue electronic money (wallets, prepaid cards, stored balances) in addition to providing payment services. Higher minimum capital than a PI.

Useful for: wallets, prepaid, platform balances.
SafeguardingClient funds

Safeguarding of funds

The obligation to keep client funds segregated and protected in case the institution becomes insolvent. A central piece of the application file.

Evidence: segregated accounts + safeguarding policy.
PSD2Regulatory framework

Payment Services Directive 2

The European framework that regulates payment services and sets obligations on SCA, access to accounts (open banking), reporting and transparency of information.

Key: strong authentication + incident reporting.
PISP / AISPOpen banking

Payment initiation / Account aggregation

PSD2 license types for operating in open banking: the PISP initiates payments from accounts held elsewhere and the AISP aggregates banking information, without handling client funds.

They require specific registration with the Bank of Spain.
DORAICT resilience

Digital Operational Resilience Act

EU regulation applicable since January 2025 that requires an ICT risk management framework, business continuity, incident reporting and oversight of critical providers.

Applies to all PIs, EMIs and investment firms authorized in the EU.
Programme of operationsApplication file

Regulatory business plan

The core document of the application file: it describes the services to be provided, the business model, the operating structure, the clients and the partners of the future institution.

It must be consistent with every policy in the application file.
Key functionsGovernance

Key Function Holders

The heads of compliance, internal audit, risk and AML/CFT, who must be identified, be fit and proper and have real capacity to perform their role.

Evidence: appointments, CVs, independence policies.
Critical outsourcingThird parties

Outsourcing of essential functions

Technology or essential service providers must be documented: contracts, SLAs, security, continuity and an exit plan for contingencies.

The Bank of Spain requires traceability of critical outsourcing.
SCAAuthentication

Strong Customer Authentication

Strong Customer Authentication required by PSD2: at least two independent factors (knowledge, possession, inherence) for electronic payments and online account access.

Exemptions: low value, trusted beneficiaries (whitelisting), recurring transactions.
SEPAEU payments

Single Euro Payments Area

A single euro payments area that standardizes credit transfers and direct debits across 36 European countries. SEPA Credit Transfer (SCT), SEPA Instant Payments (SCT Inst) and SEPA Direct Debit (SDD).

Access for authorized PIs via the EPC schemes.
OCI / SEPBLACAML/CFT

Internal control body and representative

The OCI (internal control body) is the internal body responsible for AML/CFT compliance. A representative before SEPBLAC, Spain's Financial Intelligence Unit and anti-money laundering authority, must be appointed.

A mandatory piece of the application file: formal appointment of a suitable profile.
📥 Free download

PI License Checklist: 8 key steps of the application file

The practical guide we use with our clients to prepare a solid, defensible application file before the Bank of Spain: regulatory fit, capital, programme of operations, governance, safeguarding, AML/CFT, DORA and ongoing compliance.

  • The 8 key building blocks of the application file (regulatory fit, capital, safeguarding, AML, DORA…)
  • The documents the supervisor expects in each block
  • Typical mistakes that delay or block authorization
✓

Done! Your checklist is downloading

If the download hasn't started, click the button. Have a specific question about your PI project? Diego replies on WhatsApp.

Book a call

Tell us about your project and we will explain how to structure your payment institution license in an operational way and with the shortest possible processing time.

Legislation and supervision: the sources that apply

The laws, authorities and public registers that govern the activity of payment institutions in Spain and the EU. Keep them at hand throughout the process.

Regulatory framework for payment institutions in Spain: PSD2 and Royal Decree-law 19/2018

Payment institutions in Spain are mainly governed by Royal Decree-law 19/2018 of 23 November on payment services and other urgent financial measures, which transposes Directive (EU) 2015/2366 (PSD2). Authorization and supervision are the responsibility of the Bank of Spain, which assesses the suitability of the project, the governance structure, the strength of the application file and the real operational capacity of the future institution.

Payment services that require a PSD2 license in Spain

The services that require a PI license include: services enabling cash to be placed on an account, cash withdrawal services, execution of payment transactions (credit transfers, direct debits, card payments), issuing of payment instruments, money remittance and payment initiation services (PISP). Providing any of these services without prior authorization is a very serious infringement.

Capital and governance requirements

The required minimum capital ranges from €20,000 to €125,000 depending on the payment services to be provided. In addition, the institution must maintain sufficient own funds in line with its volume of activity. The application file must include a programme of operations, internal policies, a governance structure with properly accredited key functions and an internal control system proportionate to the risk.

Safeguarding of client funds

One of the most critical obligations of a payment institution is the safeguarding of users' funds: they must be held in segregated accounts at credit institutions or invested in secure, liquid assets. Compliance with this obligation is directly supervised, and a breach can lead to immediate interim measures.

DORA and digital operational resilience

Since January 2025, the DORA Regulation has applied to all payment institutions authorized in the EU. It requires an ICT risk management framework, a business continuity policy, incident logging and reporting, digital resilience testing and oversight of critical technology providers. PIs that have not adapted their ICT risk management system are exposed to supervisory measures.

PSD2 Royal Decree-law 19/2018 Bank of Spain DORA AML/KYC Safeguarding PSD3